|
|
|
95 days, 22 hours, 33 minutes
ago
Thursday, November 05, 2009 10:12:22 PM
GMT
Thursday, November 05, 2009 12:15:50 PM
GMT
|
|
www.techcrunch.com --
A Facebook developer named Yvo Schaap has uncovered a massive security flaw present on both Facebook and MySpace that would give hackers the ability to steal all of your account data, including your photos, personal messages, and basically everything else you've ever put on the social networks, without you ever realizing it.
Schaap stumbled upon the exploit and contacted both Facebook and MySpace. According to his blog MySpace has since fixed the bug, and while his blog indicates that Facebook is still working on it we've confirmed that they've fixed it as well (we're waiting on a statement from MySpace). So what exactly could the exploit do? From Schaap's blog:
You don't need much time to think of all the ways this could be exploited. All what has to happen is a active session, or a "auto login"-cookie and a URL which hosts a exploiting Flash file. For example when accessed, a automatic "post update" could be made, that would lure friends of the user to access the exploit URL, and the exploit would spread virally. An more invasive and hidden exploit could harvest all the users personal photo's, data and messages to a central server without any trace, and there is no reason why this wouldn't be happening already with both Facebook and MySpace data.
|
|
tags:
Company & Product Profiles, facebook, myspace
|
|
No comments yet, be the first one to post comment.